|
Message-ID: <3408.1208430638@devserv.devel.redhat.com> Date: Thu, 17 Apr 2008 07:10:38 -0400 From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Subject: Re: CVE request: firefox 2.0.14 ( Crash in JavaScript garbage collector) > > And again, are pure browser crashers considered security relevant? I'd do so, > as e.g. placing a crashing gif on e.g. some popular wiki could cause much > trouble: > http://www.securityfocus.com/bid/27243 > (I think it's still unfixed) > As the advisory states: We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past. It is almost certain that given how Firefox is crashing, someone with the time and know how could leverage this to execute arbitrary code. -- JB
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.